Technology · Ebook
External Secrets Operator: Syncing Secrets into Kubernetes
by Shriira Press
Almost every cluster needs credentials it should never store itself, and almost every organisation already keeps those credentials in AWS Secrets Manager, HashiCorp Vault, Google Secret Manager, or Azure Key Vault. The External Secrets Operator is the bridge between the two worlds: a Kubernetes operator that reads secrets from an external system of record and projects them into ordinary Secret objects, keeping them refreshed as the source changes. This book starts with the problem of secret sprawl, then works through the operator's architecture as controllers and custom resources, the SecretStore that holds authentication, the ExternalSecret that declares what to fetch, the broad provider ecosystem, the templating engine and PushSecret, and finally how to run the operator well in production.
Contents
- 1Preface
- 2Chapter 1 — The Problem of Secrets in Kubernetes
- 3Chapter 2 — What the External Secrets Operator Does
- 4Chapter 3 — Architecture and Components
- 5Chapter 4 — SecretStores and Authentication
- 6Chapter 5 — The ExternalSecret Resource
- 7Chapter 6 — Providers Across the Ecosystem
- 8Chapter 7 — Templating and Pushing Secrets
- 9Chapter 8 — Running the Operator in Practice
